New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

FortiManager MCP Server

236 tools. 129 can modify or destroy data without limits.

35 destructive tools with no built-in limits. Policy required.

Last updated:

129 can modify or destroy data
107 read-only
236 tools total

Community server · catalogue entry checked 29/08/2026

How to control FortiManager MCP Server ↓

What FortiManager MCP Server exposes to your agents

Read (107) Write / Execute (94) Destructive / Financial (35)
Critical Risk

The most dangerous FortiManager MCP Server tools

129 of FortiManager MCP Server's 236 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control FortiManager MCP Server

PolicyLayer is an MCP gateway — it sits between your AI agents and FortiManager MCP Server, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "delete_address": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "add_device": {
    "limits": [
      {
        "counter": "add_device_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "diff_adom_revision": {
    "limits": [
      {
        "counter": "diff_adom_revision_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register FortiManager MCP Server — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON FORTIMANAGER →

Instant setup, no code required.

All 236 FortiManager MCP Server tools

DESTRUCTIVE 35 tools
Destructive delete_address delete_address Destructive delete_address_group delete_address_group Destructive delete_antivirus_profile delete_antivirus_profile Destructive delete_application_list delete_application_list Destructive delete_cli_template_group Delete a CLI template group. Destructive delete_device delete_device Destructive delete_device_dhcp_server Delete a DHCP server scope from a device's device DB. Destructive delete_device_group delete_device_group Destructive delete_device_interface Delete an interface from a device's device DB. Destructive delete_device_ipsec_phase1_interface delete_device_ipsec_phase1_interface Destructive delete_device_ipsec_phase2_interface Delete an IPsec phase2-interface from a device's device DB. Destructive delete_device_vap Delete a wireless VAP from a device's device DB. Destructive delete_device_wtp delete_device_wtp Destructive delete_devices_bulk delete_devices_bulk Destructive delete_dlp_profile delete_dlp_profile Destructive delete_dnsfilter_profile delete_dnsfilter_profile Destructive delete_firewall_policies_bulk delete_firewall_policies_bulk Destructive delete_firewall_policy delete_firewall_policy Destructive delete_ips_sensor delete_ips_sensor Destructive delete_local_in_policy delete_local_in_policy Destructive delete_local_in_policy6 delete_local_in_policy6 Destructive delete_package delete_package Destructive delete_script Delete a CLI script. Destructive delete_sdwan_template Delete an SD-WAN template. Destructive delete_service delete_service Destructive delete_service_group delete_service_group Destructive delete_ssl_ssh_profile delete_ssl_ssh_profile Destructive delete_task delete_task Destructive delete_waf_profile delete_waf_profile Destructive delete_webfilter_profile delete_webfilter_profile Destructive remove_device_from_group remove_device_from_group Destructive remove_devices_from_group_bulk remove_devices_from_group_bulk Destructive remove_group_from_group remove_group_from_group Destructive remove_ips_sensor_signature_override remove_ips_sensor_signature_override Destructive trigger_fmg_restore trigger_fmg_restore
WRITE 76 tools
Write add_device add_device Write add_device_to_group add_device_to_group Write add_devices_bulk add_devices_bulk Write add_devices_to_group_bulk add_devices_to_group_bulk Write add_group_to_group add_group_to_group Write add_ips_sensor_signature_override add_ips_sensor_signature_override Write add_model_device add_model_device Write assign_package assign_package Write assign_sdwan_template Assign an SD-WAN template to a device. Write assign_sdwan_template_bulk assign_sdwan_template_bulk Write assign_system_template Assign a system template to a device. Write assign_system_template_bulk assign_system_template_bulk Write assign_template_group Assign a template group to a device. Write assign_vap_to_wtp_profile assign_vap_to_wtp_profile Write clone_package clone_package Write create_address_fqdn create_address_fqdn Write create_address_group create_address_group Write create_address_host create_address_host Write create_address_range create_address_range Write create_address_subnet create_address_subnet Write create_antivirus_profile create_antivirus_profile Write create_application_list create_application_list Write create_cli_template_group Create a new CLI template group. Write create_device_dhcp_server create_device_dhcp_server Write create_device_group create_device_group Write create_device_interface create_device_interface Write create_device_ipsec_phase1_interface create_device_ipsec_phase1_interface Write create_device_ipsec_phase2_interface create_device_ipsec_phase2_interface Write create_device_sniffer create_device_sniffer Write create_device_vap create_device_vap Write create_device_wtp create_device_wtp Write create_dlp_profile create_dlp_profile Write create_dnsfilter_profile create_dnsfilter_profile Write create_firewall_policy create_firewall_policy Write create_ips_sensor create_ips_sensor Write create_local_in_policy create_local_in_policy Write create_local_in_policy6 create_local_in_policy6 Write create_package create_package Write create_sdwan_template Create a new SD-WAN template. Write create_service_group create_service_group Write create_service_icmp create_service_icmp Write create_service_tcp_udp create_service_tcp_udp Write create_ssl_ssh_profile create_ssl_ssh_profile Write create_waf_profile create_waf_profile Write create_webfilter_profile create_webfilter_profile Write lock_adom lock_adom Write move_firewall_policy move_firewall_policy Write resolve_datasource resolve_datasource Write unassign_sdwan_template Unassign an SD-WAN template from a device. Write unassign_system_template Unassign a system template from a device. Write unlock_adom unlock_adom Write update_address update_address Write update_address_group update_address_group Write update_antivirus_profile update_antivirus_profile Write update_application_list update_application_list Write update_device update_device Write update_device_dhcp_server update_device_dhcp_server Write update_device_interface update_device_interface Write update_device_ipsec_phase1_interface update_device_ipsec_phase1_interface Write update_device_ipsec_phase2_interface update_device_ipsec_phase2_interface Write update_device_sslvpn_settings update_device_sslvpn_settings Write update_device_sslvpn_web_portal update_device_sslvpn_web_portal Write update_device_wtp update_device_wtp Write update_device_wtp_profile_radio update_device_wtp_profile_radio Write update_dlp_profile update_dlp_profile Write update_dnsfilter_profile update_dnsfilter_profile Write update_firewall_policy update_firewall_policy Write update_ips_sensor update_ips_sensor Write update_local_in_policy update_local_in_policy Write update_local_in_policy6 update_local_in_policy6 Write update_script Update an existing CLI script. Write update_service update_service Write update_service_group update_service_group Write update_ssl_ssh_profile update_ssl_ssh_profile Write update_waf_profile update_waf_profile Write update_webfilter_profile update_webfilter_profile
READ 107 tools
Read diff_adom_revision diff_adom_revision Read diff_device_revision diff_device_revision Read diff_policy_package diff_policy_package Read find_duplicate_objects find_duplicate_objects Read find_fortimanager_tool Discover FortiManager tools by operation name/keywords. Read find_object_usage find_object_usage Read get_address get_address Read get_address_group get_address_group Read get_adom get_adom Read get_adom_revision Get one ADOM DB revision's metadata. Read get_antivirus_profile get_antivirus_profile Read get_application_list get_application_list Read get_cli_template_group Get details of a CLI template group. Read get_device get_device Read get_device_client_location get_device_client_location Read get_device_interface_config get_device_interface_config Read get_device_interfaces get_device_interfaces Read get_device_ipsec_phase1_interface get_device_ipsec_phase1_interface Read get_device_ipsec_phase2_interface get_device_ipsec_phase2_interface Read get_device_realtime_status get_device_realtime_status Read get_device_revision get_device_revision Read get_device_sdwan get_device_sdwan Read get_device_sdwan_monitor get_device_sdwan_monitor Read get_device_sslvpn_settings get_device_sslvpn_settings Read get_device_sslvpn_web_portal get_device_sslvpn_web_portal Read get_device_status get_device_status Read get_device_wtp get_device_wtp Read get_device_wtp_profile get_device_wtp_profile Read get_dlp_profile get_dlp_profile Read get_dnsfilter_profile get_dnsfilter_profile Read get_firewall_policy get_firewall_policy Read get_firmware_upgrade_path get_firmware_upgrade_path Read get_firmware_upgrade_report get_firmware_upgrade_report Read get_fmg_license get_fmg_license Read get_ha_status get_ha_status Read get_ips_sensor get_ips_sensor Read get_local_in_policy get_local_in_policy Read get_local_in_policy6 get_local_in_policy6 Read get_package get_package Read get_packet_capture_status get_packet_capture_status Read get_policy_services get_policy_services Read get_preview_result get_preview_result Read get_script Get details of a specific CLI script. Read get_script_log_latest Get the latest script execution log. Read get_script_log_output get_script_log_output Read get_script_log_summary Get script execution log summary. Read get_sdwan_template Get details of a specific SD-WAN template. Read get_service get_service Read get_service_group get_service_group Read get_ssl_ssh_profile get_ssl_ssh_profile Read get_system_status get_system_status Read get_system_template Get details of a specific system template. Read get_task get_task Read get_template Get details of a specific provisioning template. Read get_template_group Get details of a template group. Read get_waf_profile get_waf_profile Read get_webfilter_profile get_webfilter_profile Read health_check Check FortiManager MCP server health and connection status. Read list_address_groups list_address_groups Read list_addresses list_addresses Read list_adom_revisions list_adom_revisions Read list_adoms list_adoms Read list_antivirus_profiles list_antivirus_profiles Read list_application_lists list_application_lists Read list_available_firmware list_available_firmware Read list_cli_template_groups List CLI template groups in an ADOM. Read list_device_dhcp_servers List DHCP servers configured in a device's device DB. Read list_device_groups list_device_groups Read list_device_ipsec_phase1_interfaces list_device_ipsec_phase1_interfaces Read list_device_ipsec_phase2_interfaces List IPsec phase2-interface (tunnel/selector) definitions in a device's device DB. Read list_device_revisions list_device_revisions Read list_device_vaps List wireless VAPs (SSIDs) in a device's device DB. Read list_device_vdoms list_device_vdoms Read list_device_wtp_profiles List FortiAP (WTP) profiles in a device's device DB. Read list_device_wtps list_device_wtps Read list_devices list_devices Read list_dlp_profiles list_dlp_profiles Read list_dnsfilter_profiles list_dnsfilter_profiles Read list_firewall_policies list_firewall_policies Read list_firmware_images list_firmware_images Read list_fortimanager_categories List all FortiManager tool categories and their tool counts. Read list_ips_sensor_signature_overrides list_ips_sensor_signature_overrides Read list_ips_sensors list_ips_sensors Read list_local_in_policies list_local_in_policies Read list_local_in_policies6 list_local_in_policies6 Read list_packages list_packages Read list_packet_captures list_packet_captures Read list_policy_revisions list_policy_revisions Read list_scripts list_scripts Read list_sdwan_templates list_sdwan_templates Read list_service_groups list_service_groups Read list_services list_services Read list_ssl_ssh_profiles list_ssl_ssh_profiles Read list_system_templates list_system_templates Read list_tasks list_tasks Read list_template_groups list_template_groups Read list_templates list_templates Read list_waf_profiles list_waf_profiles Read list_webfilter_profiles list_webfilter_profiles Read policy_lookup policy_lookup Read reload_device_list reload_device_list Read revert_adom_revision revert_adom_revision Read revert_device_revision revert_device_revision Read revert_firewall_policy revert_firewall_policy Read search_devices search_devices Read search_firewall_policies search_firewall_policies Read search_objects search_objects

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about FortiManager MCP Server

Can an AI agent delete data through the FortiManager MCP Server MCP server? +

Yes. The FortiManager MCP Server server exposes 35 destructive tools including delete_address, delete_address_group, delete_antivirus_profile. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through FortiManager MCP Server? +

The FortiManager MCP Server server has 76 write tools including add_device, add_device_to_group, add_devices_bulk. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach FortiManager MCP Server.

How many tools does the FortiManager MCP Server MCP server expose? +

236 tools across 4 categories: Destructive, Execute, Read, Write. 107 are read-only. 129 can modify, create, or delete data.

How do I enforce a policy on FortiManager MCP Server? +

Register the FortiManager MCP Server MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every FortiManager MCP Server tool call.

Deterministic rules across all 236 FortiManager MCP Server tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

236 FortiManager MCP Server tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from FortiManager MCP Server's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.